音频水印会削弱反欺骗检测效果,提出新框架缓解此问题。
The Impact of Audio Watermarking on Audio Anti-Spoofing Countermeasures
- 构建含水印的反欺骗数据集,研究水印对检测的影响。
- 水印密度越高,误检率(EER)越高,性能显著下降。
- 适合语音安全、反欺骗系统研发者关注,尤其需加水印场景。
本文首次研究音频水印对反欺骗对策的影响。尽管反欺骗系统对语音应用安全至关重要,但广泛使用的音频水印(原用于版权保护)的影响仍不明确。我们通过在现有反欺骗数据集上应用多种手工和神经水印方法,构建了名为Watermark-Spoofing的数据集。实验表明,水印会持续降低反欺骗性能,且水印密度与等错误率(EER)呈正相关。为此,我们提出知识保全水印学习(KPWL)框架,使模型能适应水印带来的分布偏移,同时保持原有领域的欺骗检测能力。研究揭示音频水印是一种被忽视的领域偏移,并建立了首个具备水印鲁棒性的反欺骗系统基准。相关协议已公开于https://github.com/Alphawarheads/Watermark_Spoofing.git。
原文摘要 · Abstract (English)
This paper presents the first study on the impact of audio watermarking on spoofing countermeasures. While anti-spoofing systems are essential for securing speech-based applications, the influence of widely used audio watermarking, originally designed for copyright protection, remains largely unexplored. We construct watermark-augmented training and evaluation datasets, named the Watermark-Spoofing dataset, by applying diverse handcrafted and neural watermarking methods to existing anti-spoofing datasets. Experiments show that watermarking consistently degrades anti-spoofing performance, with higher watermark density correlating with higher Equal Error Rates (EERs). To mitigate this, we propose the Knowledge-Preserving Watermark Learning (KPWL) framework, enabling models to adapt to watermark-induced shifts while preserving their original-domain spoofing detection capability. These findings reveal audio watermarking as a previously overlooked domain shift and establish the first benchmark for developing watermark-resilient anti-spoofing systems. All related protocols are publicly available at https://github.com/Alphawarheads/Watermark_Spoofing.git
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。